2025 CVE Vulnerabilities
45,153 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11119 | MEDIUM | 6.1 | 0.4% | Sep 28, 2025 | A security flaw has been discovered in itsourcecode Hostel Management System 1.0. Impacted is an unknown function of the... |
| CVE-2025-11112 | MEDIUM | 6.1 | 0.4% | Sep 28, 2025 | A security vulnerability has been detected in PHPGurukul Employee Record Management System 1.3. This impacts an unknown ... |
| CVE-2025-11081 | MEDIUM | 5.5 | 0.2% | Sep 27, 2025 | A vulnerability was detected in GNU Binutils 2.45. This issue affects the function dump_dwarf_section of the file binuti... |
| CVE-2025-11080 | MEDIUM | 4.3 | 0.2% | Sep 27, 2025 | A security vulnerability has been detected in zhuimengshaonian wisdom-education up to 1.0.4. This vulnerability affects ... |
| CVE-2025-11073 | MEDIUM | 4.7 | 1.9% | Sep 27, 2025 | A vulnerability was detected in Keyfactor RG-EW5100BE EW_3.0B11P280_EW5100BE-PRO_12183019. The affected element is an un... |
| CVE-2025-11069 | MEDIUM | 4.8 | 0.3% | Sep 27, 2025 | A vulnerability was determined in westboy CicadasCMS 1.0. Affected by this issue is some unknown functionality of the fi... |
| CVE-2025-11068 | MEDIUM | 4.8 | 0.3% | Sep 27, 2025 | A vulnerability was found in westboy CicadasCMS 1.0. Affected by this vulnerability is an unknown functionality of the f... |
| CVE-2025-11067 | MEDIUM | 4.8 | 0.3% | Sep 27, 2025 | A vulnerability has been found in Projectworlds Visitor Management System 1.0. Affected is an unknown function of the fi... |
| CVE-2025-9944 | MEDIUM | 4.3 | 0.1% | Sep 27, 2025 | The Professional Contact Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an... |
| CVE-2025-9899 | MEDIUM | 6.1 | 0.1% | Sep 27, 2025 | The Trust Reviews plugin for Google, Tripadvisor, Yelp, Airbnb and other platforms plugin for WordPress is vulnerable to... |
| CVE-2025-9898 | MEDIUM | 4.3 | 0.1% | Sep 27, 2025 | The cForms – Light speed fast Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versi... |
| CVE-2025-9896 | MEDIUM | 4.3 | 0.1% | Sep 27, 2025 | The HidePost plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3.... |
| CVE-2025-9894 | MEDIUM | 4.3 | 0.1% | Sep 27, 2025 | The Sync Feedly plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1... |
| CVE-2025-9893 | MEDIUM | 4.3 | 0.1% | Sep 27, 2025 | The VM Menu Reorder plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i... |
| CVE-2025-11051 | MEDIUM | 6.5 | 0.2% | Sep 27, 2025 | A vulnerability has been found in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknow... |
| CVE-2025-10499 | MEDIUM | 4.3 | 0.2% | Sep 27, 2025 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Request ... |
| CVE-2025-10498 | MEDIUM | 5.4 | 0.2% | Sep 27, 2025 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Request ... |
| CVE-2025-8440 | MEDIUM | 6.4 | 0.2% | Sep 27, 2025 | The Team Members plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the first and last name fields in... |
| CVE-2025-36239 | MEDIUM | 6.1 | 0.2% | Sep 27, 2025 | IBM Storage TS4500 Library 1.11.0.0 and 2.11.0.0 is vulnerable to cross-site scripting. This vulnerability allows an u... |
| CVE-2025-59938 | MEDIUM | 6.5 | 0.3% | Sep 27, 2025 | Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions starting from ... |
| CVE-2025-36144 | MEDIUM | 5.5 | 0.1% | Sep 27, 2025 | IBM Lakehouse (watsonx.data 2.2) stores potentially sensitive information in log files that could be read by a local use... |
| CVE-2025-57692 | MEDIUM | 6.8 | 0.3% | Sep 26, 2025 | PiranhaCMS 12.0 allows stored XSS in the Text content block of Standard and Standard Archive Pages via /manager/pages, e... |
| CVE-2025-11034 | MEDIUM | 4.3 | 0.4% | Sep 26, 2025 | A vulnerability was found in Dibo Data Decision Making System up to 2.7.0. The affected element is the function download... |
| CVE-2025-26258 | MEDIUM | 6.1 | 0.2% | Sep 26, 2025 | Sourcecodester Employee Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via 'Add Designation.' |
| CVE-2025-11031 | MEDIUM | 5.5 | 0.8% | Sep 26, 2025 | A flaw has been found in DataTables up to 1.10.13. The affected element is an unknown function of the file /examples/res... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now